Somebody at your company used an AI tool this week without mentioning it to anyone. A salesperson asked ChatGPT to tighten up a proposal, or the office manager pasted a spreadsheet in to find the pattern in it. That is not a discipline problem. The tools are free and genuinely useful, and nobody ever told them not to.

Which makes the AI policy question less about AI than it sounds. What you actually need to know is what company and client information is leaving the building through a chat box nobody manages, and who is answerable when the output turns out to be wrong. A policy is how you settle both in writing, once, instead of case by case after something has already gone out the door.

This guide walks through what a workable AI acceptable use policy contains and what each clause is protecting you from, then gives you a starter template to copy.

What goes wrong without one

Client information lands with a vendor you never vetted. The free tier of a consumer AI product is a different product from the business tier that sits behind a commercial agreement. Someone pastes in a client contract to get a summary, or drops in a customer export to fix the formatting, and that material is now held by a company you have no relationship with. Nothing dramatic happens on the day. It becomes a problem the first time a client asks you directly whether their information has ever been put into an AI tool, because “I do not know” is the worst available answer.

Wrong answers travel under your name. AI writing is fluent whether or not it is correct, which makes it harder to catch than a weak draft from a person. Invented case law in a memo, or a figure in a proposal that nobody sourced. Every tool gets things wrong sometimes. The damage here comes from the wrong thing reaching a client, because it read well and no one had been told to check it.

Nobody owns it when it surfaces. With no written rule, the conversation after an incident turns into an argument about what a reasonable person should have assumed. That conversation is bad for everyone in it, and it usually ends in an informal ban that pushes AI use onto personal phones and out of sight. A short policy replaces the argument with a reference.

What a good policy actually covers

Five parts, matching the five numbered sections in the template below. Each one is there because of a specific thing that goes wrong without it.

Approved tools

A list of tools staff may use, plus a route to get something added to it. What this protects against is the shadow IT version of AI, where every person picks their own tool and you have no idea which vendors are holding your work.

Name the tier, not just the brand. ChatGPT Team and free ChatGPT are the same interface with different data terms, and the same split runs across the market. A policy that says “ChatGPT is fine” grants considerably more than you meant it to.

This is also the section where most businesses realize the policy is overdue. Microsoft 365 already includes Copilot Chat in the business plans, and the 2026 plan changes pushed an upgraded version of it into Business Basic, Standard, and Premium. If you pay for Microsoft 365, you have an AI tool deployed to every user whether anyone has discussed it or not. “We do not use AI here” is usually already false.

Data rules

The clause everything else leans on: a plain list of what may never go into an AI tool unless your business has an agreement with that vendor covering your data. Client names and identifying details, employee records, and financial records all belong on that list. Passwords stay out either way, because a credential in someone else’s system is compromised no matter what the paperwork says, and so does anything under an NDA, since a deal you sign with a vendor cannot loosen a confidentiality promise you made to a client.

Write it in the categories your staff recognize from their own work, and keep the abstractions out. “Confidential information” makes every employee the judge of their own case. “Do not paste client names, invoices, or anything out of the HR folder” is a rule someone can follow at speed, which is the only speed at which it will get followed.

Give people somewhere to ask, too. Most near-misses are a person who paused, could not tell which side of the line they were on, and took a guess because asking felt like an imposition.

Human review

Anything a tool helped produce that leaves the company gets read by the person sending it, and that person owns what it says.

This clause does the most work per word, because it puts accountability where it already sat. Staff sometimes hear it as distrust of AI. In practice it gives them cover. Once it is clear that the sender owns the output, using AI to get a first draft stops being a question anyone needs to ask permission for.

Disclosure

Two things belong here: how you answer when a client asks whether AI was involved, and what happens when a contract already speaks to it.

The first is a values question with a practical edge. Answer honestly, because the alternative is a denial that a single forwarded email can undo. The second is the part people forget. Client master service agreements and vendor terms increasingly carry AI clauses, and your staff are not going to read those. The policy has to say plainly that where a contract restricts AI use or requires disclosure, the contract wins.

Ownership

A named person, a review cadence, and a contact for new tool requests. An unowned policy is a document rather than a control, and the way you can tell is that nobody knows who to ask when a new tool shows up. That owner does not have to be technical. They have to be someone who can say yes or no to a tool request without escalating it.

Ownership is also where the AI policy joins the rest of your written rules instead of sitting off to the side. If your password standard still demands symbols and quarterly resets, the same review is a good moment to bring it in line with current NIST guidance.

The template

Copy this into a document, fill in the brackets, and delete anything that does not apply.

AI Acceptable Use Policy for [Company Name]

Effective [date]. Owner: [name and role].

1. Approved tools. Staff may use the AI tools on our approved list: [for example: ChatGPT Team, Microsoft Copilot, Google Gemini, Claude]. Anything not on the list, including free consumer versions of listed tools, needs sign-off from [policy owner] before first use.

2. Data rules. Passwords and credentials never go into an AI tool, agreement or no agreement, and the same goes for anything covered by an NDA. Never enter client names or client-identifying details, employee records, or financial records into an AI tool, unless [Company Name] has a business agreement with that tool’s vendor that covers our data. When in doubt, ask [policy owner] before pasting.

3. Human review. Anything AI helped produce that leaves the company, including client emails, proposals, code, and published content, gets reviewed by the person sending it. You are responsible for what you ship, whatever wrote the first draft.

4. Disclosure. If a client asks whether AI was used, we answer honestly. Where a contract requires disclosure or restricts AI use, that contract wins over this policy.

5. Ownership and questions. [Name and role] owns this policy and reviews it quarterly. New tool requests and questions go to [contact].

Rolling it out

Send it, do not file it. A policy that lands in a shared folder has not been adopted. Send it as a short note from the owner explaining what it is and why it exists, and say plainly that the point is to make AI use safe to do out in the open.

Walk through it once, for ten minutes. Use a team meeting you already have. Read the data rules out loud and give two examples from your own business, one clearly fine and one clearly not, because the edge cases people actually hit are closer to those than to anything in the document. End by naming the person to ask, and mean it, since a policy that makes people afraid to ask questions just teaches them to stay quiet.

Revisit it quarterly. Put it on the calendar with the owner’s name attached. The quarterly pass is short: is the approved list still accurate, did any tool on it change its terms, and what did people ask for that is not on it yet.

Writing the policy is step one, and it is the cheap step. Your policy might say nobody pastes client data into an unapproved tool, but whether your Microsoft 365 tenant would notice or stop it is a separate question, and Secure Score is a reasonable place to start reading the answer for your own tenant. The gap between a rule people agree to and a rule the system enforces is worth understanding before you lean on either one, and it is its own topic.

Making the written rule and the technical reality match is what a security program is for. Most of that work lands in the Microsoft 365 tenant where the AI tools already are. Get in touch and we will tell you what your staff can currently do with company data, and what the policy would change.